cbcvebase.
CVE-2026-1584
published 2026-04-09

CVE-2026-1584: A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with an…

PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.38%
69.1th percentile
A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with an invalid Pre-Shared Key (PSK) binder value during the TLS handshake. This can lead to a NULL pointer dereference, causing the server to crash and resulting in a remote Denial of Service (DoS) condition.

Affected

2 ranges
VendorProductVersion rangeFixed in
debiangnutls28< gnutls28 3.8.12-1 (forky)gnutls28 3.8.12-1 (forky)
langroidlangroid>= 0 < 0.59.320.59.32

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa9.8CRITICAL
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.